- Access exclusive content
- Connect with peers
- Share your expertise
- Find support resources
05-08-2022 04:30 PM
Hello Admins,
We use Analytics BIOC Rules. But where is the Causality Change? No of alerts rising, but where to see who, why and what?
Thank you!
BR
Rob
05-09-2022 12:54 AM - edited 05-09-2022 01:58 AM
Hi @Cyber1985
you can go to the Incidents page, then to the alerts table there you can scroll to the right to see all the columns and fields populated, CGO (Causality Group Owner), paths, processes....
If you click on the 3 dots menu at the top right corner of the alerts table you will see more columns and fields that are not shown by default. You can select them and incorporate them to your view.
I believe that you'll find there all you'r looking for.
I hope this helps.
KR,
Luis
Just as an example:
05-09-2022 11:52 AM
Hi @Cyber1985 It appears that you looking for guidance on how to investigate Analytics / Analytics BIOC alert sources. From the Alert Table, you may right-click to "Investigate Causality Chain" to view the event table. In this view and depending on the analytics alert type, then you may have host, endpoint connection status, IP, MAC, account of interest (E.g. Username), Parent process ID located at the top left-hand corner of the causality view. If you click the red icon in the view, then you can view context about the alert. If you hover you mouse over the related processes in the causality, then you can review process and analytics profiles information to support your investigation. If you click on the processes in the casualty view, then you will be presented with all applicable actions (E.g. Process, Network, File, Network Connections).
In the alert table, then you can also leverage "Pivot to View" options to conduct additional analysis on user / asset in scope.
Click Accept as Solution to acknowledge that the answer to your question has been provided.
The button appears next to the replies on topics you’ve started. The member who gave the solution and all future visitors to this topic will appreciate it!
These simple actions take just seconds of your time, but go a long way in showing appreciation for community members and the LIVEcommunity as a whole!
The LIVEcommunity thanks you for your participation!